Whew! Log from SAS
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 10/07/2011 at 05:58 PM
Application Version : 5.0.1128
Core Rules Database Version : 7771
Trace Rules Database Version: 5583
Scan type : Complete Scan
Total Scan Time : 01:13:58
Operating System Information
Windows XP Home Edition 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator
Memory items scanned : 418
Memory threats detected : 0
Registry items scanned : 38256
Registry threats detected : 2
File items scanned : 46757
File threats detected : 122
Disabled.TaskManager
HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM#DISABLETASKMGR
HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM#DISABLETASKMGR
Adware.Tracking Cookie
C:\Documents and Settings\user\Cookies\5V10NSR7.txt [ /kontera.com ]
C:\Documents and Settings\user\Cookies\GIV7J2MZ.txt [ /r1-ads.ace.advertising.com ]
C:\Documents and Settings\user\Cookies\OFMFKD22.txt [ /tacoda.at.atwola.com ]
C:\Documents and Settings\user\Cookies\WYGZ2PGZ.txt [ /media6degrees.com ]
C:\Documents and Settings\user\Cookies\QCJDMNKG.txt [ /at.atwola.com ]
C:\Documents and Settings\user\Cookies\811ISHR3.txt [ /adxpose.com ]
C:\Documents and Settings\user\Cookies\D8PTR9BU.txt [ /liveperson.net ]
C:\Documents and Settings\user\Cookies\ZQ1FFBI4.txt [ /liveperson.net ]
C:\Documents and Settings\user\Cookies\XHGTJYWK.txt [ /casalemedia.com ]
C:\Documents and Settings\user\Cookies\BC1Z6V8X.txt [ /mediaplex.com ]
C:\Documents and Settings\user\Cookies\D9SEX1I3.txt [ /network.realmedia.com ]
C:\Documents and Settings\user\Cookies\FYZ3K306.txt [ /eset.122.2o7.net ]
C:\Documents and Settings\user\Cookies\43O360ZS.txt [ /zedo.com ]
C:\Documents and Settings\user\Cookies\PBEZHMBW.txt [ /fastclick.net ]
C:\Documents and Settings\user\Cookies\59W6I2VM.txt [ /sales.liveperson.net ]
C:\Documents and Settings\user\Cookies\58JINBON.txt [ /hpi.rotator.hadj7.adjuggler.net ]
C:\Documents and Settings\user\Cookies\Q4FKXIBR.txt [ /ads.bridgetrack.com ]
C:\Documents and Settings\user\Cookies\PZRHXAJQ.txt [ /rotator.hadj7.adjuggler.net ]
C:\Documents and Settings\user\Cookies\5UWHGXOT.txt [ /adserver.adtechus.com ]
C:\Documents and Settings\user\Cookies\O6KBKI4I.txt [ /ads.bleepingcomputer.com ]
C:\Documents and Settings\user\Cookies\INK43RGU.txt [ /intermundomedia.com ]
C:\Documents and Settings\user\Cookies\ZBZ0V9RJ.txt [ /pro-market.net ]
C:\Documents and Settings\user\Cookies\7C3SRDNC.txt [ /atdmt.com ]
C:\Documents and Settings\user\Cookies\582H4QVQ.txt [ /serving-sys.com ]
C:\Documents and Settings\user\Cookies\NDJQ4Y0E.txt [ /anrtx.tacoda.net ]
C:\Documents and Settings\user\Cookies\2DVFVG8Y.txt [ /revsci.net ]
C:\Documents and Settings\user\Cookies\HE7GPULQ.txt [ /collective-media.net ]
C:\Documents and Settings\user\Cookies\0OR0VX8N.txt [ /yieldmanager.net ]
C:\Documents and Settings\user\Cookies\ZJOCHPA4.txt [ /ar.atwola.com ]
C:\Documents and Settings\user\Cookies\ZML1SWNO.txt [ /doubleclick.net ]
C:\Documents and Settings\user\Cookies\BF8E00C1.txt [ /ad.yieldmanager.com ]
C:\Documents and Settings\user\Cookies\6KC0A0NZ.txt [ /insightexpressai.com ]
C:\Documents and Settings\user\Cookies\NDR81GBP.txt [ /ad.wsod.com ]
C:\Documents and Settings\user\Cookies\HGHQ6LQS.txt [ /ads.undertone.com ]
C:\Documents and Settings\user\Cookies\R2YHOCT7.txt [ /advertising.com ]
C:\Documents and Settings\user\Cookies\ZJLT9EN0.txt [ /invitemedia.com ]
C:\Documents and Settings\user\Cookies\42B3K88A.txt [ /apmebf.com ]
C:\Documents and Settings\user\Cookies\K93D7ESQ.txt [ /realmedia.com ]
C:\Documents and Settings\user\Cookies\SZRRILCE.txt [ /lucidmedia.com ]
C:\Documents and Settings\user\Cookies\HRMUXD3V.txt [ /imrworldwide.com ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\BVIWZK2T.txt [ Cookie:administrator@apmebf.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\MBRO3M9I.txt [ Cookie:administrator@atdmt.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\27IF8JMR.txt [ Cookie:administrator@media6degrees.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\RDQ24X8U.txt [ Cookie:administrator@adsonar.com/adserving ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\RQ4VZPWB.txt [ Cookie:administrator@ru4.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\TKE4G34A.txt [ Cookie:administrator@revsci.net/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\6MXA1EXV.txt [ Cookie:administrator@tribalfusion.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\421YRY2S.txt [ Cookie:administrator@tacoda.at.atwola.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\VB6169NF.txt [ Cookie:administrator@at.atwola.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\RYYX472T.txt [ Cookie:administrator@citi.bridgetrack.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\2DR83E6K.txt [ Cookie:administrator@adxpose.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\GGCK44NM.txt [ Cookie:administrator@lucidmedia.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\LPM6KEET.txt [ Cookie:administrator@banners.andomedia.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\DUAT23T9.txt [ Cookie:administrator@dc.tremormedia.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\WXS5IQT4.txt [ Cookie:administrator@content.yieldmanager.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\HBNXMX2J.txt [ Cookie:administrator@www.myaccountaccess.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\NY9DZEXE.txt [ Cookie:administrator@kontera.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\FTJLAF7R.txt [ Cookie:administrator@interclick.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\4TPAMHP6.txt [ Cookie:administrator@doubleclick.net/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\RPAZQS1H.txt [ Cookie:administrator@pointroll.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\78CDP9HE.txt [ Cookie:administrator@serving-sys.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\FRRB36ZO.txt [ Cookie:administrator@a1.interclick.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\XE08YAEL.txt [ Cookie:administrator@mediaplex.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\YABFXSYO.txt [ Cookie:administrator@advertising.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\39LFROQ8.txt [ Cookie:administrator@r1-ads.ace.advertising.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\2ZDSJOJ7.txt [ Cookie:administrator@accountonline.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\9BKHV7HR.txt [ Cookie:administrator@collective-media.net/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\UG7XZ4Q9.txt [ Cookie:administrator@intermundomedia.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\86NIYTGA.txt [ Cookie:administrator@ar.atwola.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\QCN8XRFR.txt [ Cookie:administrator@content.yieldmanager.com/ak/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\40SWBUS2.txt [ Cookie:administrator@zedo.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\ZSAC4TC3.txt [ Cookie:administrator@adinterax.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\776W5W8N.txt [ Cookie:administrator@yieldmanager.net/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\JT49C7VD.txt [ Cookie:administrator@ad.yieldmanager.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\ME4GVIG4.txt [ Cookie:administrator@insightexpressai.com/ ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\Cookies\I6FEETUL.txt [ Cookie:administrator@anrtx.tacoda.net/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\R3NYZE84.txt [ Cookie:user1@zedo.com/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\VKWP1Z9Q.txt [ Cookie:user1@imrworldwide.com/cgi-bin ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\R3N2TMN3.txt [ Cookie:user1@lucidmedia.com/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\3E0QAJJ9.txt [ Cookie:user1@doubleclick.net/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\6YPLMD7U.txt [ Cookie:user1@ad.yieldmanager.com/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\5L90HN21.txt [ Cookie:user1@tribalfusion.com/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\DBIYLD62.txt [ Cookie:user1@r1-ads.ace.advertising.com/ ]
C:\DOCUMENTS AND SETTINGS\user1\Cookies\3HZGTR91.txt [ Cookie:user1@invitemedia.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\6OAODFK6.txt [ Cookie:system@ru4.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\KQVZOMY4.txt [ Cookie:system@imrworldwide.com/cgi-bin ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\XVGP32TK.txt [ Cookie:system@fastclick.net/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\EIKD1ABL.txt [ Cookie:system@stat.onestat.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\30R807LD.txt [ Cookie:system@media6degrees.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\FXPJZ7RB.txt [ Cookie:system@revsci.net/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\OUL7LB2E.txt [ Cookie:system@atdmt.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\CNSIHTNH.txt [ Cookie:system@doubleclick.net/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\L47HUVQ3.txt [ Cookie:system@lucidmedia.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\RET05LHT.txt [ Cookie:system@www.gourmandia.com/advertisement/includes/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\WA1TLKXO.txt [ Cookie:system@collective-media.net/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\XP011UW9.txt [ Cookie:system@realmedia.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\FI5ITYA2.txt [ Cookie:system@yieldmanager.net/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\1G011W31.txt [ Cookie:system@apmebf.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\9IB4SJKF.txt [ Cookie:system@casalemedia.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\799H25CC.txt [ Cookie:system@bizzclick.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\TND5OHQR.txt [ Cookie:system@adserver.adtechus.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\H7G8JBZB.txt [ Cookie:system@questionmarket.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\L7YGSW5J.txt [ Cookie:system@r1-ads.ace.advertising.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\CT41DOBT.txt [ Cookie:system@statcounter.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\MP6MMMHY.txt [ Cookie:system@cdn.jemamedia.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\8TS4ILFZ.txt [ Cookie:system@advertising.com/ ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Cookies\FZ7E5RBT.txt [ Cookie:system@2o7.net/ ]
ad.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.Admin.000\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\N2GR6K8S ]
ad.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\user\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\MKQ647GF ]
objects.tremormedia.com [ C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\3AHA42H6 ]
Trace.Known Threat Sources
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Local Settings\Temporary Internet Files\Content.IE5\76AI73HJ\style[1].css [ cache:shopica.com ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Local Settings\Temporary Internet Files\Content.IE5\90VHP7DW\js[1].js [ cache:shopica.com ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Local Settings\Temporary Internet Files\Content.IE5\G9QSXNRF\sp[1].gif [ cache:shopica.com ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Local Settings\Temporary Internet Files\Content.IE5\90VHP7DW\shopica_logo_bott[1].gif [ cache:shopica.com ]
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\Local Settings\Temporary Internet Files\Content.IE5\76AI73HJ\async_ads_rs[1].htm [ cache:shopica.com ]
Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1403\A0262219.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1403\A0262220.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1403\A0262221.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1404\A0274395.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1404\A0274396.EXE
Trojan.Agent/Gen-Zmozer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1417\A0318031.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1417\A0318032.DLL